{"id":"GO-2023-1892","summary":"Kubernetes mountable secrets policy bypass in k8s.io/kubernetes","details":"Kubernetes mountable secrets policy bypass in k8s.io/kubernetes","aliases":["CVE-2023-2728","GHSA-cgcv-5272-97pr"],"modified":"2026-02-04T02:24:08.126010Z","published":"2024-08-20T20:31:35Z","related":["CGA-rf9v-fqxc-27vj"],"database_specific":{"review_status":"REVIEWED","url":"https://pkg.go.dev/vuln/GO-2023-1892"},"references":[{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-cgcv-5272-97pr"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2023/07/06/3"},{"type":"WEB","url":"https://github.com/kubernetes/kubernetes/issues/118640"},{"type":"WEB","url":"https://github.com/kubernetes/kubernetes/pull/118356"},{"type":"WEB","url":"https://github.com/kubernetes/kubernetes/pull/118471"},{"type":"WEB","url":"https://github.com/kubernetes/kubernetes/pull/118473"},{"type":"WEB","url":"https://github.com/kubernetes/kubernetes/pull/118474"},{"type":"WEB","url":"https://github.com/kubernetes/kubernetes/pull/118512"},{"type":"WEB","url":"https://groups.google.com/g/kubernetes-security-announce/c/vPWYJ_L84m8"}],"affected":[{"package":{"name":"k8s.io/kubernetes","ecosystem":"Go","purl":"pkg:golang/k8s.io/kubernetes"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.24.15"},{"introduced":"1.25.0"},{"fixed":"1.25.11"},{"introduced":"1.26.0"},{"fixed":"1.26.6"},{"introduced":"1.27.0"},{"fixed":"1.27.3"}]}],"ecosystem_specific":{},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2023-1892.json"}}],"schema_version":"1.7.3"}